GLPI 11.0.8 / 10.0.26 — critical RCE via form import and complete MFA bypass in the public-sector ITSM platform
GLPI 11.0.8 and 10.0.26 shipped on 2026-06-24, fixing 16 vulnerabilities (16 addressed in 11.0.8, 9 in 10.0.26), but the CVEs were publicly disclosed on 2026-07-21 and CERT-FR published its advisory CERTFR-2026-AVI-0909 on 2026-07-22 — the in-window event that brings the flaws to defenders' attention (GLPI Project, 2026-06-24; CERT-FR, 2026-07-22). Two flaws are critical: CVE-2026-48482, remote code execution via GLPI 11's native form-import feature — an unsafe parsing/deserialization path in the import handler that gives an attacker who can submit a crafted form file code execution with application privileges; and CVE-2026-52848, a complete bypass of GLPI 11's multi-factor authentication mechanism, defeating the 2FA hardening the 11.x branch specifically introduced (GLPI Project, 2026-06-24). High-severity entries add exploitation depth: account takeover by brute-forcing the 2FA code itself (no rate-limiting on OTP verification, CVE-2026-49470), privilege escalation through the authtype API (CVE-2026-53625), SQL injection in dropdown and history-tab components (CVE-2026-47678, CVE-2026-53629), arbitrary file deletion (CVE-2026-47679) and arbitrary document read (CVE-2026-53626), plus stored and reflected XSS (IT-Connect, 2026-06-25). Affected are GLPI 11.0.x before 11.0.8 and all versions before 10.0.26; no source in this run reports in-the-wild exploitation.
[SECURITY - ==CRITICAL== 11.0] RCE via Form import (CVE-2026-48482)
De multiples vulnérabilités ont été découvertes dans GLPI. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.
Defender actions
- Update internet-facing GLPI instances to 11.0.8 (11.0.x) or 10.0.26 (10.0.x) now — the release fixes a critical form-import RCE and a complete MFA bypass that together defeat the authentication hardening the 11.x branch specifically introduced.
ATT&CK mapping
4 techniques mapped from the cited reporting · MITRE ATT&CK v19.1
Initial Access TA0001
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Persistence TA0003
T1556.006Modify Authentication Process: Multi-Factor Authentication
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Defense Impairment TA0112
T1556.006Modify Authentication Process: Multi-Factor Authentication
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Credential Access TA0006
T1110Brute Force
Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.
T1556.006Modify Authentication Process: Multi-Factor Authentication
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.